{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T15:14:14Z","timestamp":1773155654833,"version":"3.50.1"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"5-6","license":[{"start":{"date-parts":[[2021,8,28]],"date-time":"2021-08-28T00:00:00Z","timestamp":1630108800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,8,28]],"date-time":"2021-08-28T00:00:00Z","timestamp":1630108800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Ann. Telecommun."],"published-print":{"date-parts":[[2022,6]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>This paper proposes a general-purpose anomaly detection mechanism for Internet backbone traffic named GAMPAL (General-purpose Anomaly detection Mechanism using Prefix Aggregate without Labeled data). GAMPAL does not require labeled data to achieve general-purpose anomaly detection. For scalability to the number of entries in the BGP RIB (Border Gateway Protocol Routing Information Base), GAMPAL introduces prefix aggregate. The BGP RIB entries are classified into prefix aggregates, each of which is identified with the first three AS (Autonomous System) numbers in the AS_PATH attribute. GAMPAL establishes a prediction model for traffic sizes based on past traffic sizes. It adopts a LSTM-RNN (Long Short-Term Memory Recurrent Neural Network) model that focuses on the periodicity of the Internet traffic patterns at a weekly scale. The validity of GAMPAL is evaluated using real traffic information, BGP RIBs exported from the WIDE backbone network (AS2500), a nationwide backbone network for research and educational organizations in Japan, and the dataset of an ISP (Internet Service Provider) in Spain. As a result, GAMPAL successfully detects anomalies such as increased traffic due to an event, DDoS (Distributed Denial of Service) attacks targeted at a stub organization, a connection failure, an SSH (Secure Shell) scan attack, and anomaly spam.<\/jats:p>","DOI":"10.1007\/s12243-021-00874-8","type":"journal-article","created":{"date-parts":[[2021,8,28]],"date-time":"2021-08-28T10:02:36Z","timestamp":1630144956000},"page":"437-454","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["GAMPAL: an anomaly detection mechanism for Internet backbone traffic by flow size prediction with LSTM-RNN"],"prefix":"10.1007","volume":"77","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0750-2348","authenticated-orcid":false,"given":"Taku","family":"Wakui","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takao","family":"Kondo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fumio","family":"Teraoka","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,8,28]]},"reference":[{"key":"874_CR1","unstructured":"Fraleigh C, Tobagi F, Diot C (2003) Provisioning ip backbone networks to support latency sensitive traffic. In: IEEE INFOCOM 2003. Twenty-second annual joint conference of the IEEE computer and communications societies (IEEE Cat. No.03CH37428), vol 1, pp 375\u2013385"},{"issue":"1","key":"874_CR2","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/j.jnca.2012.09.004","volume":"36","author":"H Liao","year":"2016","unstructured":"Liao H, Lin C R, Lin Y, Tung K (2016) Intrusion detection system: A comprehensive review. J Netw Comput Appl 36(1):16\u201324","journal-title":"J Netw Comput Appl"},{"key":"874_CR3","doi-asserted-by":"crossref","unstructured":"Kumar R, Sharma D (2018) HyINT Signature-anomaly intrusion detection system. In: Proc. of ICCCNT 2018, pp 1\u20137","DOI":"10.1109\/ICCCNT.2018.8494088"},{"key":"874_CR4","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1016\/j.comnet.2015.12.008","volume":"97","author":"J Kwon","year":"2016","unstructured":"Kwon J, Leea J, Lee H, Perrig A (2016) PsyBoG: A scalable botnet detection method for large-scale DNS traffic. Comput Netw 97:48\u201373","journal-title":"Comput Netw"},{"key":"874_CR5","doi-asserted-by":"crossref","unstructured":"Tang T A, Mhamdi L, McLernon D, Zaidi S, Ghogho M (2018) Deep recurrent neural network for intrusion detection in SDN-based networks. In: Proceedings of IEEE NetSoft 2018, pp 202\u2013206","DOI":"10.1109\/NETSOFT.2018.8460090"},{"issue":"1","key":"874_CR6","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1109\/TNSM.2017.2750906","volume":"15","author":"O Ibidunmoye","year":"2018","unstructured":"Ibidunmoye O, Rezaie A, Elmroth E (2018) Adaptive anomaly detection in performance metric streams. IEEE Trans Netw Serv Manag 15(1):217\u2013231","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"874_CR7","doi-asserted-by":"crossref","unstructured":"Chen S, Chen Y, Tzeng W (2018) Effective botnet detection through neural networks on convolutional features. In: Proceedings of IEEE TrustCom\/BigDataSE 2018, pp 372\u2013378","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00062"},{"key":"874_CR8","doi-asserted-by":"crossref","unstructured":"Petrie C, King T (2017) Multi-threaded routing toolkit (MRT) routing information export format with BGP additional path extensions. RFC 8050 IETF","DOI":"10.17487\/RFC8050"},{"key":"874_CR9","unstructured":"NAVIDIA cuDNN. https:\/\/developer.nvidia.com\/cudnn(Last accessed 20 Aug 2019)"},{"key":"874_CR10","unstructured":"Chainer: A flexible framework for neural networks. https:\/\/chainer.org\/"},{"key":"874_CR11","unstructured":"WIDE backbone. http:\/\/two.wide.ad.jp\/"},{"key":"874_CR12","doi-asserted-by":"crossref","unstructured":"Maci\u00e1-Fern\u00e1ndez G, Camacho J, Mag\u00e1n-Carri\u00f3n R, Garc\u00eda-Teodoro P, Ther\u00f3n R (2017) UGR\u201916: a new dataset for the evaluation of cyclostationarity-based network IDSs. Computers & Security: 73","DOI":"10.1016\/j.cose.2017.11.004"},{"key":"874_CR13","unstructured":"RIPE NCC RIS Raw Data. http:\/\/www.ripe.net\/projects\/ris\/rawdata.html"},{"key":"874_CR14","doi-asserted-by":"crossref","unstructured":"Flanagan K, Fallon E, Jacob P, Awad A, Connolly P (2019) 2D2N A dynamic degenerative neural network for classification of images of live network data. In: Proceedings of IEEE CCNC 2019, pp 1\u20137","DOI":"10.1109\/CCNC.2019.8651695"},{"key":"874_CR15","unstructured":"NSL-KDD dataset. https:\/\/www.unb.ca\/cic\/datasets\/nsl.html (Last accessed 20 Aug 2019)"},{"key":"874_CR16","doi-asserted-by":"crossref","unstructured":"Kathareios G, Anghel A, Mate A, Clauberg R, Gusat M (2017) Catch it if you can: Real-time network anomaly detection with low false alarm rates. In: Proceedings of IEEE ICMLA 2017, pp 924\u2013929","DOI":"10.1109\/ICMLA.2017.00-36"},{"key":"874_CR17","doi-asserted-by":"crossref","unstructured":"Cho K, Fukuda K, Esaki H, Kato A (2006) The impact and implications of the growth in residential user-to-user traffic. In: Proceedings of ACM SIGCOMM 2006, pp 207\u2013218","DOI":"10.1145\/1151659.1159938"},{"key":"874_CR18","unstructured":"nfdump. http:\/\/nfdump.sourceforge.net. (Last accessed 20 Aug 2019)"},{"key":"874_CR19","unstructured":"bgpdump. https:\/\/bitbucket.org\/ripencc\/bgpdump\/wiki\/Home. (Last accessed 20 Aug 2019)"},{"key":"874_CR20","unstructured":"Lazaris A, Prasanna V K (2019) An lstm framework for modeling network traffic. In: Proceedings of 4th IFIP\/IEEE symposium on integrated network and service management, pp 19\u201324"},{"key":"874_CR21","doi-asserted-by":"crossref","unstructured":"Papagiannaki K, Taft N, Zhang Z, Diot C (2003) Long-term forecasting of internet backbone traffic: observations and initial models. In: IEEE INFOCOM 2003. Twenty-second Annual Joint Conference of the IEEE Computer and Communications Societies (IEEE Cat. No.03CH37428), vol 2, pp 1178\u20131188","DOI":"10.1109\/INFCOM.2003.1208954"},{"issue":"8","key":"874_CR22","doi-asserted-by":"publisher","first-page":"2111","DOI":"10.1109\/TSP.2003.814521","volume":"51","author":"C Barakat","year":"2003","unstructured":"Barakat C, Thiran P, Iannaccone G, Diot C, Owezarski P (2003) Modeling internet backbone traffic at the flow level. IEEE Trans Signal Process 51(8):2111\u20132124","journal-title":"IEEE Trans Signal Process"},{"key":"874_CR23","unstructured":"Red-Black-Tree. https:\/\/developer.nvidia.com\/cudnn (Last accessed 20 Aug 2019)"},{"key":"874_CR24","unstructured":"TeamYoutube. https:\/\/twitter.com\/TeamYouTube\/status\/1052393799815589889?ref_src=twsrc"},{"key":"874_CR25","unstructured":"NETSCOUT. https:\/\/www.netscout.com\/blog\/asert\/call-arms-apple-remote-management-service-udp"},{"key":"874_CR26","doi-asserted-by":"crossref","unstructured":"Smith C L (2003) Understanding concepts in the defence in depth strategy. In: IEEE 37th Annual 2003 International Carnahan Conference onSecurity Technology, 2003. Proceedings, pp 8\u201316","DOI":"10.1109\/CCST.2003.1297528"}],"container-title":["Annals of Telecommunications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-021-00874-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s12243-021-00874-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-021-00874-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,13]],"date-time":"2022-06-13T08:36:32Z","timestamp":1655109392000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s12243-021-00874-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,28]]},"references-count":26,"journal-issue":{"issue":"5-6","published-print":{"date-parts":[[2022,6]]}},"alternative-id":["874"],"URL":"https:\/\/doi.org\/10.1007\/s12243-021-00874-8","relation":{},"ISSN":["0003-4347","1958-9395"],"issn-type":[{"value":"0003-4347","type":"print"},{"value":"1958-9395","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,8,28]]},"assertion":[{"value":"31 August 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 August 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 August 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}